Feith is FedRAMP Moderate Authorized · High In Process Read the release
Feith
Higher education

One platform for the campus record.

StudentDocs runs admissions, financial aid, the registrar, sponsored research, and the seven other offices that own records, on the same architecture that holds federal records under FedRAMP and DISA-JITC. Every access writes to one append-only audit log.

11
Campus offices on one platform, admissions through the graduate school.
6
Compliance regimes held on a single append-only audit log.
47 yrs
Building federal records technology since 1979.
FedRAMP
Moderate authorized; DISA-JITC certified since 2002.

FERPA · GLBA · HIPAA · NIST 800-171 · state public records · Title IX, with every access on one append-only audit log. FedRAMP Moderate authorized · DoDM 8180.01 aligned (JITC-tested under the legacy 5015.02-STD) · built and owned in Fort Washington, PA.

Higher-ed records in 2026

Six regimes. Eleven offices. One records officer holding the bag.

FERPA governs the student record. GLBA governs the aid file. NIST 800-171 covers anything CUI that arrives with a federal grant. State law and Title IX layer their own rules on top. And the records don't sit in one system.

  • FERPA the student record
  • GLBA Safeguards the financial-aid file
  • HIPAA campus health, where it applies
  • NIST 800-171 CUI from federal research
  • State public records open-records requests
  • Title IX investigation evidence

They live in Banner, PeopleSoft, Workday, M365, Google Workspace, file shares, and the paper folders some offices still keep, and the records officer is responsible for all of it. StudentDocs takes responsibility for the records once they exist, wherever they live. Capture normalizes the metadata, the vault holds the authoritative copy, the audit log records every access, and retention runs against each office's schedule.

Students raising their hands in a university lecture hall
The lecture hall is where the record begins, and StudentDocs governs it from the day it's created to the day it's disposed.
Eleven offices · five modules · one platform

Every office on campus owns records. StudentDocs covers every office.

Eleven departmental workflows, organized into five family modules, each on the same vault, identity layer, and audit log, each shipping with the document types, workflows, and retention rules the family actually uses.

Student records

Admissions · Financial Aid · Registrar / Transcripts · Bursar · Graduate School

The offices that own the official student record. Applications and transcripts arrive from Slate, Common App, and the SIS; award files run through verification and appeals; transcripts release inside the 45-day FERPA window.

Compliance FERPA · directory-information rules · GLBA Safeguards · Title IV evidence · NSLDS / COD retention.

Research & sponsored programs

Sponsored Programs · Research

Federally-funded research carries federal records obligations. Grant files, IRB and IACUC records, and CUI from research contracts sit in the same vault, under the same audit log, as the registrar's transcripts.

Compliance NIST 800-171 · CMMC · ITAR · EAR · NIH and NSF retention.

People & faculty

HR / Faculty · Advancement / Alumni

Personnel files, tenure dossiers, search-committee records, and faculty contracts, plus gift records, donor files, and planned-giving documentation, separated from FERPA-protected records at the access layer where policy requires it.

Compliance EEOC · tenure schedule · CASE reporting standards · IRS substantiation.

Legal & public records

General Counsel / Public Records · Title IX / Conduct

Open-records requests, subpoena response, litigation hold, and e-discovery, alongside Title IX files with separated roles, an evidence chain, and litigation hold. Both run on the same exemption logic and redaction tooling as Feith's federal FOIA Workbench.

Compliance State public-records law · current Title IX requirements · Clery Act overlap · litigation hold.

Student health

Student Health (HIPAA-adjacent)

Counseling, health-services, vaccination, and accommodation records, held under the FERPA medical-record exception or under HIPAA where the campus health center is a covered entity, with ADA accommodation records kept separate.

Compliance FERPA medical-record exception · HIPAA where applicable · ADA accommodation rules.
FERPA, by design

FERPA is an architecture decision, built in from the start.

StudentDocs treats FERPA as a structural requirement. Every access to a student record writes to an append-only log, the 45-day access window is a tracked workflow, and the school-official exception is logged with the determination that justified it.

  • Every read, write, and disclosure of a FERPA-covered record writes to the append-only audit log: user, role, action, timestamp, record ID, and reason code.
  • The 45-day access window runs as a tracked case. The clock starts on the request; the package returned to the requester is itself recorded.
  • Directory-information opt-outs apply at the field level: a student can opt out of one field and stay opted in elsewhere.
  • The school-official exception requires a logged determination at the moment of access, so auditors see the basis, not just the access.
  • Disclosures under FERPA exceptions (subpoena, health-and-safety emergency, accrediting organization) write to a separate channel with the legal basis attached. AI can classify and route intake faster; the disclosure decision stays with the records officer.
Every access writes one entry
User · role
Who touched the record
Action
View · update · disclose
Reason code
Required, e.g. transcript request
Stamp
Timestamp + record ID, immutable
Append-only · hash-chained · forwarded to your SIEM.
45-day access window: a tracked case

The clock starts on the request. The package returned to the requester is itself recorded.

Sponsored research · CUI · ITAR · CMMC

The research office that holds federal contracts.

Federally-funded research carries federal records obligations: CUI markings, NIST 800-171 controls, ITAR and EAR export controls, CMMC posture for DoD work. StudentDocs handles them on the same platform that handles your registrar's transcripts. The research office stops standing up parallel systems to satisfy compliance.

  1. 1
    Marked at capture
    The CUI marking is applied on intake and travels with the record.
  2. 2
    Enforced at access
    Checked at the user, record, and project level on every read; U.S.-person status verified.
  3. 3
    Audited to a control
    Each access ties to a NIST 800-171 control: your evidence, ready for assessment.
  • CUI is marked at capture, propagated through the workflow, and enforced at access.
  • NIST 800-171 control mappings are provided per project; SSP and POA&M evidence is pulled from the audit log.
  • ITAR and EAR access restrictions are enforced at the user, record, and project level, with U.S.-person verification logged.
  • CMMC posture is maintained per project; Level 2 controls are available on the single-tenant deployment, subject to your C3PAO.
  • Sponsored-programs systems (Cayuse, Kuali, InfoEd) integrate as capture sources, so grant files flow into the same vault.
General counsel · public records · Title IX

The records workflows under the most scrutiny. Both run on StudentDocs.

State public-records requests arrive with a clock attached. Title IX files have to be retained, redacted, disclosed selectively, and held for years. Both run on the same vault, with the same exemption logic and redaction tooling as Feith's federal FOIA Workbench.

The foundation underneath

One identity. One audit log. Every record, every system.

StudentDocs runs on the identity layer your campus already uses, and runs lifecycle and audit across records wherever they live, without forcing a migration.

One identity layer

CAS, Shibboleth, SAML, OIDC, AD / LDAP, and MFA: the login your campus already uses, with role attributes derived from the SIS. Need-to-know access is enforced per record, per field, per workflow step.

One audit log

Append-only, hash-chained, anti-tamper, with Splunk / SIEM forwarding. The audit architecture that holds federal records under DISA-JITC certification holds your campus access log too.

Records stay where they live

Records in M365 stay in M365; records in Google stay in Google; file shares stay file shares. StudentDocs runs retention, holds, disposition, and audit against them in place: the vault is the source of truth, the storage stays where users work.

Migration from your current ECM

Move from the ECM you have today to the platform you need tomorrow.

Most campuses come from OnBase, Banner Document Management, Laserfiche, Perceptive Content, or a homegrown stack. The migration runs in three phases, one at a time, so the path stops being all-or-nothing.

  1. 1

    Capture-only deployment

    Records flow into StudentDocs from your existing systems while your incumbent ECM keeps running. Identity and audit consolidate first; the new vault carries everything that arrives after go-live without touching the legacy archive.

    8 to 16 weeks to deploy. No system retires in this phase.

  2. 2

    Department-by-department cutover

    Pick the office with the most pain. Sponsored Programs and Financial Aid are common first choices. Move that office's workflow, then repeat on a schedule the campus controls. Each cutover is independent.

    4 to 8 weeks per department, sequenced to your priorities.

  3. 3

    Sunset, optional

    Some campuses retire the incumbent ECM once active workflows have moved; others keep it as a read-only archive. Either way, the StudentDocs vault holds the authoritative copy of anything still in flight.

    When the campus is ready. The decision is reversible.

Institutional

Forty-seven years of federal records work, now in your registrar's office.

A state university CIO doesn't have to argue the architecture from first principles. The vault, audit log, identity layer, and lifecycle services under StudentDocs are the same components the National Archives and the Department of Defense evaluated, against their own standards, before authorizing them.

  1. 1979
    Feith Systems founded in Fort Washington, PA, with federal records from day one.
  2. 2002
    DoD 5015.02-STD certification achieved through DISA-JITC, renewed continuously until the standard was retired in 2023, now DoDM 8180.01.
  3. 2025
    USDA-sponsored FedRAMP Moderate authorization.
Talk to a StudentDocs lead

Bring the records architecture to your campus.

A 45-minute walkthrough with a StudentDocs lead, usually with the records officer and one other stakeholder. We work through your actual records workflow and show you what StudentDocs does in the office with the most pain.

On the call
  • Your records workflow walked through with a StudentDocs lead who knows FERPA.
  • How FERPA, NIST 800-171, state public records, and Title IX apply to your stack.
  • A pricing range: by department module, by records under management, or a campus-wide site license.
Book a walkthrough
Available through
GSA Schedule 36SEWP VIWRPDOC CATTSFedRAMP Marketplace
Request pricing ›